PT-2026-83969 · Doccano · Doccano
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Doccano Open Source Annotation Tools for Machine Learning Practitioners versions prior to 1.8.6
Description
Improper access controls exist within the Project Example Detail Endpoint. A remote attacker can exploit this issue via the
ExampleDetail() function located at the '/v1/projects/1/examples/' endpoint, potentially leading to unauthorized access.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/v1/projects/1/examples/' endpoint to minimize the risk of exploitation.
Exploit
Incorrect Privilege Assignment
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Doccano